PHP Live! Multiple Cross-Site Scripting Vulnerabilities

An attacker can trigger these vulnerabilities by enticing a victim user to follow a malicious URI.

Example URIs have been provided:
/transcripts.php?action=view&deptid=1&userid=0&search_string=[XSS]
http://www.example.com/index.php?l=[XSS]
/phplive/message_box.php?theme=&l=ezpub&x=1&deptid=[XSS]
/phplive/message_box.php?theme=&l=admin&x=[XSS]


 

Privacy Statement
Copyright 2010, SecurityFocus